Responsible AI
AI Usage Policy
Last updated: October 2, 2026
The rules our team follows whenever AI touches a client project. The values behind them are in our AI Principles.
1. Purpose and scope
This policy sets out how people at Setubo, Inc. and our engineering center, Setubo Private Limited, use AI tools: chat assistants, coding agents, and AI models, on client projects and on our own products.
It applies to everyone who works on a Setubo project. Where a client's agreement sets stricter rules, the agreement wins.
2. Approved tools and accounts
- We use only AI tools the company has approved, through company-managed accounts. Personal accounts are never used for client work.
- We use providers' business or API plans whose terms say they don't use our inputs to train their models.
- Access is set up per person and removed when someone leaves the team.
3. What never goes into an AI tool
Nobody on our team puts any of the following into an AI tool:
- Passwords, API keys, tokens, or any other secrets.
- Personal data of a client's customers or users.
- Anything a client has asked us to keep out of AI tools.
When a project needs AI but its data can't leave the client's infrastructure, we run open-weight models on the client's own servers instead.
4. Transparency and client choice
- Clients can always ask which AI tools and models work on their project, and we tell them.
- A client can choose to have no AI on their project, or on part of it. We then work without it, or use private models the client controls.
5. Engineering rules
- AI agents work inside a sandboxed harness, with access only to what a task needs.
- Every AI-made change is reviewed before it ships: an AI reviewer checks it, and a senior engineer approves it.
- Automated tests run on the critical paths of every build, and a senior QA engineer tests each release end to end.
- AI-generated code is checked so that nothing with an incompatible licence ends up in a client's product.
- Authentication, data handling, and payments are reviewed by a senior engineer before launch.
6. Ownership
Work produced with AI is treated exactly like any other work: once invoices are paid, the code, designs, and intellectual property belong to the client, and they live in the client's repository and cloud accounts.
7. Accountability
Our engineers are responsible for everything they deliver, however it was first written. Anyone who suspects this policy was broken, or that data reached an AI tool it shouldn't have, reports it to their project lead straight away so it can be dealt with under the client's agreement.
8. Review and contact
We review this policy and our AI Principles at least once a year, and sooner when tools or risks change.
Questions about how we use AI on your project? Email support@setubo.com.